Description
Versions of node-rules
prior to 5.0.0 are vulnerable to Command Injection. The package fails to sanitize input rules and passes it directly to an eval
call when using the fromJSON
function. This may allow attackers to execute arbitrary code in the system if the rules are user-controlled.
Recommendation
Update the node-rules
package to the latest compatible version. Followings are version details:
- Affected version(s): < 5.0.0
- Patched version(s): 5.0.0
References
Related Issues
- lobe-chat has an Open Redirect - CVE-2025-59426
- Cross-site Scripting in cesium - CVE-2023-48094
- Cross-site Scripting in epubjs - CVE-2021-33040
- Remote Memory Disclosure in ws - CVE-2016-10518
- Tags:
- npm
- node-rules
Anything's wrong? Let us know Last updated on October 06, 2023